1z0-821 Oracle Solaris 11 System Administration Practice Questions
Prepare for 1z0-821 with more than an answer.
- Exam fee
- $300 USD
- Level
- Associate
- Valid for
- No expiration
Domains covered on the exam 8
- Installing Oracle Solaris 1112%
- Updating and Managing Software Packages15%
- Administering Services13%
- Setting Up and Administering Data Storage14%
- Administering Oracle Solaris Zones13%
- Administering Physical Network12%
- Setting Up and Administering User Accounts11%
- Controlling Access to Systems and Files10%
- 1
User jack logs in to host Solaris and executes the following command sequence:
Which three statements are correct?

Show answer details
Correct answer: D, E, F
D, E, F
D, E, F
D, E, F
- 2
You are installing the Solaris 11 Operation System by using the Text Installer. A panel prompts you to create a root password and a user account.
Which four describe your options for completing this panel of the Installation?Show answer details
Correct answer: A, B, D, G
A, B, D, G -- Explanation: A: You are not required to create a user account.
B: You must create a root password.
D: lfyou create a user account in this panel, you need to provide both the user's password and a root password.
In this case, root will be a role assigned to the user.
G: If you do not create a user account, you still need to provide a root password.
In this case, root will be a regular user.A, B, D, G -- Explanation: A: You are not required to create a user account.
B: You must create a root password.
D: lfyou create a user account in this panel, you need to provide both the user's password and a root password.
In this case, root will be a role assigned to the user.
G: If you do not create a user account, you still need to provide a root password.
In this case, root will be a regular user.A, B, D, G -- Explanation: A: You are not required to create a user account.
B: You must create a root password.
D: lfyou create a user account in this panel, you need to provide both the user's password and a root password.
In this case, root will be a role assigned to the user.
G: If you do not create a user account, you still need to provide a root password.
In this case, root will be a regular user.A, B, D, G -- Explanation: A: You are not required to create a user account.
B: You must create a root password.
D: lfyou create a user account in this panel, you need to provide both the user's password and a root password.
In this case, root will be a role assigned to the user.
G: If you do not create a user account, you still need to provide a root password.
In this case, root will be a regular user. - 3
You upgraded your serverto Oracle Solaris 11 and you imported zpool (pool1)thatwas created in Solaris 10. You need to create an encrypted ZFS file system in pool1, butfirst you need to make sure that your server supports ZFS encryption.
Which four statements are true for support of ZFS encryption?Show answer details
Correct answer: A, B, C, F
A, B, C, F -- Explanation: A (not H): You can use your existing storage pools as long as they are upgraded. You have the flexibility of encrypting specific file systems.
B (not E): Can I enable encryption on an existing pool?Yes, the pool must be upgraded to pool version 30 to allow encrypted ZFS file systems and volumes.
C (not D): ZFS encryption is integrated with the ZFS command set. Like other ZFS operations, encryption operations such as key changes and rekey are performed online.
F (not G): Encryption is the process in which data is encoded for privacy and a key is needed by the data owner to access the encoded data. You can set an encryption policy when a ZFS dataset is created, but the policy cannot be changed.A, B, C, F -- Explanation: A (not H): You can use your existing storage pools as long as they are upgraded. You have the flexibility of encrypting specific file systems.
B (not E): Can I enable encryption on an existing pool?Yes, the pool must be upgraded to pool version 30 to allow encrypted ZFS file systems and volumes.
C (not D): ZFS encryption is integrated with the ZFS command set. Like other ZFS operations, encryption operations such as key changes and rekey are performed online.
F (not G): Encryption is the process in which data is encoded for privacy and a key is needed by the data owner to access the encoded data. You can set an encryption policy when a ZFS dataset is created, but the policy cannot be changed.A, B, C, F -- Explanation: A (not H): You can use your existing storage pools as long as they are upgraded. You have the flexibility of encrypting specific file systems.
B (not E): Can I enable encryption on an existing pool?Yes, the pool must be upgraded to pool version 30 to allow encrypted ZFS file systems and volumes.
C (not D): ZFS encryption is integrated with the ZFS command set. Like other ZFS operations, encryption operations such as key changes and rekey are performed online.
F (not G): Encryption is the process in which data is encoded for privacy and a key is needed by the data owner to access the encoded data. You can set an encryption policy when a ZFS dataset is created, but the policy cannot be changed.A, B, C, F -- Explanation: A (not H): You can use your existing storage pools as long as they are upgraded. You have the flexibility of encrypting specific file systems.
B (not E): Can I enable encryption on an existing pool?Yes, the pool must be upgraded to pool version 30 to allow encrypted ZFS file systems and volumes.
C (not D): ZFS encryption is integrated with the ZFS command set. Like other ZFS operations, encryption operations such as key changes and rekey are performed online.
F (not G): Encryption is the process in which data is encoded for privacy and a key is needed by the data owner to access the encoded data. You can set an encryption policy when a ZFS dataset is created, but the policy cannot be changed. - 4
You suspect a problem with the oponldap package and wantto make sure thatthe files have not be modified or otherwise tampered with.
Which command would validate all of the files contained in the openldap package and report any problems?Show answer details
Correct answer: A
Explanation: pkgchk checks the accuracy of installed files or, by using the -I option, displays information about package files, pkgchk checks the integrity of directory structures and files. Discrepancies are written to standard error along with a detailed explanation of the problem.
- 5
Consider the following rule file for use with the Basic Audit Reporting Tool (BART).
CHECK all
IGNORE dirmtime/etc/security
/etc/notices
IGNORE contents/export/home
IGNORE mtime size contents/var
CHECKYou are using BART to detect inappropriate changes to the file system.
Identify the two correct statements describing the attributes recorded.Show answer details
Correct answer: D, F
D, F -- Explanation: D: According to line /etc/securityF: According to line /export/homeNot E: According to line IGNORE dirmtimeNote: In default mode, the bart compare command, as shown in the following example, checks all the files installed on the system, with the exception of modified directory timestamps (dirmtime):CHECK allIGNORE dirmtimeNote 2: The Basic Audit Reporting Tool (BART) feature of Oracle Solaris enables you to comprehensively validate systems by performing file-level checks of a system over time. By creating BART manifests, you can easily and reliably gather information aboutthe components of the software stackthat is installed on deployed systems.
BART is a useful tool for integrity management on one system or on a network of systems.D, F -- Explanation: D: According to line /etc/securityF: According to line /export/homeNot E: According to line IGNORE dirmtimeNote: In default mode, the bart compare command, as shown in the following example, checks all the files installed on the system, with the exception of modified directory timestamps (dirmtime):CHECK allIGNORE dirmtimeNote 2: The Basic Audit Reporting Tool (BART) feature of Oracle Solaris enables you to comprehensively validate systems by performing file-level checks of a system over time. By creating BART manifests, you can easily and reliably gather information aboutthe components of the software stackthat is installed on deployed systems.
BART is a useful tool for integrity management on one system or on a network of systems. - 6
To help with your troubleshooting, you need to determine the version of the OBP.
Which two commands will provide you with this information?
Show answer details
Correct answer: B, C
B, C -- Explanation: B: banner
Displays power-on banner.
The PROM displays the system banner. The following example shows a SPARCstation 2 banner. The banner for your SPARC system may be different.
SPARCstation 2, Type 4 Keyboard
ROM Rev. 2.0, 16MB memory installed. Serial # 289 Ethernet address 8:0:20:d:e2:7b, Host ID: 55000121 C: .version
Displays version and date of the boot PROM.
Note: OBP-OpenBootProm is a firmware which is placed on the sun machine's prom chip. It is a os independent user interface to deal with the sun machine's hardware components. The user interface provides one or more commands to display system information.B, C -- Explanation: B: banner
Displays power-on banner.
The PROM displays the system banner. The following example shows a SPARCstation 2 banner. The banner for your SPARC system may be different.
SPARCstation 2, Type 4 Keyboard
ROM Rev. 2.0, 16MB memory installed. Serial # 289 Ethernet address 8:0:20:d:e2:7b, Host ID: 55000121 C: .version
Displays version and date of the boot PROM.
Note: OBP-OpenBootProm is a firmware which is placed on the sun machine's prom chip. It is a os independent user interface to deal with the sun machine's hardware components. The user interface provides one or more commands to display system information. - 7
Case Study:
A company is deploying a three-tier web application on a single powerful Oracle Solaris 11 server to save costs. The architecture requires strict isolation between the Web, Application, and Database tiers. The Web tier must be accessible from the corporate network (192.168.10.0/24), but only on port 443. The Application tier must only be accessible by the Web tier. The Database tier must only be accessible by the Application tier. Communication between the Application and Database tiers should use a dedicated, high-speed virtual network.Which configuration best meets these requirements?
graph TD subgraph Corporate Network [192.168.10.0/24] A[Users] end subgraph Solaris Host subgraph Web Zone B(Web Server) end subgraph App Zone C(App Server) end subgraph DB Zone D(Database) end E[Physical NIC: net0] F[Etherstub: app_db_net] end A --> E E --> B B --> C C --> DShow answer details
Correct answer: C
This solution correctly uses zones for tier isolation. It connects the Web zone to the external network via a VNIC on
net0. It creates a private, isolated network for the App and DB tiers using an etherstub and dedicated VNICs, meeting the high-speed requirement. It also correctly places the responsibility for fine-grained access control (like port filtering) within the zones themselves using IP Filter, which is a best practice. - 8
The advantage of core tiles is that they allow you an opportunity to examine the cause of problems, so that they can be resolved. However, core files must be managed because they ________.
Show answer details
Correct answer: A
Explanation: Part of the job of cleaning up heavily loaded file systems involves locating and removing files that have not been used recently. You can locate unused files by using the Is or find commands.
Other ways to conserve disk space include emptying temporary directories such as the directories located in /var/tmp or /var/spool, and deleting core and crash dump files.
Note: Core files are generated when a process or application terminates abnormally. Core files are managed with the coreadm command.
For example, you can use the coreadm command to configure a system so that all process core files are placed in a single system directory. This means it is easier to track problems by examining the core files in a specific directory whenever a process or daemon terminates abnormally. - 9
A user account must be a member of a primary group, and may also be a member of one or more secondary groups.
What is the maximum total number of groups that one user can concurrently belong to?
Show answer details
Correct answer: B
Explanation: Each user belongs to a group that is referred to as the user’s primary group. The GID number, located in the user’s account entry within the /etc/passwd file, specifies the user’s primary group.
Each user can also belong to up to 15additional groups, known as secondary groups. In the /etc/group file, you can add users to group entries, thus establishing the user’s secondary group affiliations.
Note (4 PSARC/2009/542):his project proposes changing the maximum value for NGROUPS_MAX from 32 to 1024 by changing the definition of NGROUPS_UMAX from 32 to 1024.The use for a larger number of groups is described in CR 4088757, particular in the case of Samba servers and ADS clients; the Samba servers map every SID to a Unix group. Users with more than 32 groups SIDs are common. We've seen reports varying from '64 is enough', '128 is absolutely enough' and 'we've users with more 190 group SIDS).www.j3e.de/ngroups.html):')NGROUPS_MAX as defined by different Unix versions are as follows (http://www.j3e.de/ngroups.html):Linux Kernel )= 2.6.3 65536Linux Kernel ( 2.6.3 32Tru64 / OSF/1 32IBM AIX 5.2 64IBMAIX5.3... 6.1 128OpenBSD, NetBSD, FreeBSD, Darwin (Mac OS X) 16Sun Solaris 7, 8, 9, 10 16 (can varyfrom 0-32)HP-UX 20IRIX 16 (can vary from 0-32)Plan 9 from Bell Labs 32Minix 3 0 (Minix-vmd: 16)QNX 6.4 8 - 10
View the Exhibit to see the information taken from the installation log file.
Based on the information presented in the Exhibit, which two options describe the state of the system when the server is booted for the first time after the installation is complete?
Show answer details
Correct answer: B, D
B, D
B, D
